Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'User Account Control' = '%WINDIR%\recursos\Uac.exe'
- '<SYSTEM32>\net1.exe' USER GAIDEN /active:no
- %WINDIR%\recursos\Uac.exe
- 'tu###ngline.com':6697
- 'localhost':139
- 'localhost':445
- DNS ASK tu###ngline.com